Data Access & Processing Disclosure

GDPR & Data Protection Compliance Schedule for the Shoptest Shopify Application. This document is incorporated into the Shoptest Terms of Service and describes exactly what data Shoptest accesses, stores, and does not access when you install the App.

1. Purpose and Scope

This document describes, in factual terms, what data the Shoptest application ("Shoptest", "the App", "we") can access, collect, and store when a Merchant ("Merchant", "you") installs Shoptest on a Shopify store, and what happens to that data during use of the App and after uninstallation.

2. Roles and Responsibilities

For data relating to your own business (shop details, catalog, orders, discounts, themes, content, analytics), Shoptest processes this data to provide the service you've purchased, acting as a Data Processor under Article 28 GDPR. Where Personal Data of End Customers is incidentally present, you remain the Data Controller.

You are responsible for having a lawful basis to process your End Customers' Personal Data, for disclosing the use of apps such as Shoptest in your own privacy policy, and for responding to End Customer rights requests.

3. Authorization Mechanism

Shoptest obtains access to your store exclusively through Shopify's standard app-installation flow: an OAuth 2.0 install flow where you explicitly grant the scopes listed below, an offline access token used to make authorized API calls, and webhook subscriptions that keep data in sync in near-real time.

4. OAuth Scopes Granted at Install

• read_products — product catalog, variants, inventory, selling plans; bulk import at install, ongoing sync via webhooks.

• write_products — modify products including metafields; requested for future functionality, not currently used.

• read_orders — order data; bulk import (60-day lookback), order webhooks, payment enrichment.

• read_themes — theme list and theme asset files; identify the main theme, read and cache selected files.

• read_script_tags — third-party script tags on the storefront; read during failure analysis.

• write_script_tags — create, update or delete script tags; requested for future functionality, not currently used.

• read_content — Online Store pages, blogs and articles; seed test URLs, support broken-link crawling.

• read_discounts — discount codes and automatic discounts; bulk import and webhook sync.

• read_reports — Shopify analytics / ShopifyQL reports; aggregate session and conversion metrics.

• read_markets — Shopify Markets configuration; buyer-country and market context for multi-market tests.

Not requested: read_customers / write_customers, read_checkouts, read_inventory (standalone), read_fulfillments, read_shipping, write_themes, or any scope beyond the ten above.

Note: write_products and write_script_tags are part of the install consent even though the corresponding write code paths are unused today — you're authorizing the capability, not just today's behavior. If this changes, we'll update this page and notify you.

5. Data We Access and Store

• Shop & account data: shop name, domain, owner email/name, business address, phone, timezone, currency, plan, and the access token that authorizes API calls.

• Products & collections: titles, variants, prices, inventory, images, handles, and collection membership — kept in sync via webhooks.

• Discounts: codes, types, rules, usage counts, and eligibility (customer segment IDs only — never full customer profiles).

• Orders: order totals, status, line items, sales channel, and (where available) IP address — from the last 60 days at install, then ongoing via webhooks. We do not have write access to orders. Order webhooks can technically include End Customer email/address, but our standard sync does not persist that into a customer record.

• Payment transactions: processor-level metadata (status, gateway, amount) for orders — never full card numbers, which Shopify's API never exposes to any app.

• Themes: read-only — we read theme files to detect changes and diagnose failures; we never modify your theme.

• Online Store content: page and blog titles/handles, used to generate test targets.

• Markets & pricing: currency and region configuration, for multi-market testing.

• Analytics: aggregate session and conversion metrics only — never individual-shopper records.

• Storefront automation: beyond the Admin API, we run automated browsers against your public storefront — visiting pages, running checkout-flow tests, capturing screenshots/logs, and crawling for broken links.

6. Data We Never Access

Customer profiles, draft orders/abandoned checkouts, inventory locations, fulfillment orders, shipping labels, staff accounts, theme modification rights, metaobjects/files/translations, and Shopify Payments payout details.

7. Personal Data and Your Rights

Shoptest subscribes to Shopify's three mandatory compliance webhooks:

• customers/data_request — returns any stored Personal Data held for a specified End Customer.

• customers/redact — anonymizes or deletes an End Customer's Personal Data on request.

• shop/redact — permanently erases all data for a shop, 48 hours after the App is uninstalled.

8. Data Storage, Security, and Sub-processors

Merchant data is hosted in the United States (Render, Virginia; Google Cloud Platform, Virginia) with browser-recording infrastructure in the UK (Google Cloud Platform, London). Data is encrypted in transit (TLS) and at rest (provider-managed encryption). Our current sub-processors are listed at shoptest.ai/legal/subprocessors.

9. International Data Transfers

Because our infrastructure is hosted in the US and UK while we're established in the EU, using the App as an EEA-based Merchant involves a transfer of personal data outside the EEA. This is addressed in our Data Processing Agreement, Section 12 — including a transparent disclosure that one of our hosting providers (Render) does not currently offer Standard Contractual Clauses.

10. Purpose Limitation

Data described here is accessed solely to provide the Shoptest service: automated QA and test-flow execution, store health monitoring, broken-link and page-speed monitoring, AI-assisted failure diagnosis, and billing. It is not used to build advertising profiles, sold to third parties, or repurposed beyond delivering and improving the Shoptest service.

11. Merchant Responsibilities

Installing Shoptest doesn't transfer your own compliance obligations to us. You remain responsible for maintaining a compliant privacy policy disclosing your use of Shoptest, having a lawful basis for your End Customer data, and responding to your End Customers' data-subject requests.

12. Caveats

This document reflects what the Shoptest codebase is built to access — not a guarantee of what Shopify returns for every shop, since Shopify's Protected Customer Data rules, plan limits, and API version can restrict which fields are actually returned.

13. Contact

Hyper Effekt sp. z o.o. ("Shoptest", "the Company"). Registered office: ul. 27 Grudnia 5/5A, 61-737 Poznań, Poland. Privacy contact: legal@shoptest.ai

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.